logo

REvil Ransomware: Kaseya VSA Supply Chain Attack

ID: 1373aff2-4e8b-538a-9f07-996547b61ea8

STIX ID: report--1373aff2-4e8b-538a-9f07-996547b61ea8

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2024-11-04

Date Updated: 2026-07-16

...
...

This Cyble report dissects the July 2021 REvil (Sodinokibi) supply-chain ransomware attack that abused Kaseya VSA to distribute a signed dropper which side-loaded a malicious mpsvc.dll via MsMpEng.exe, enabling widespread encryption across MSPs and their clients; it includes technical analysis (dropper behavior, RC4-encrypted JSON configuration, registry artifacts, firewall and Defender disablement), multiple IoCs (SHA-256 hashes and a Tor C2 URL), observed victim counts and industry distribution, and actionable remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.